ci: fail lint when a test fakes macOS without @pytest.mark.macos_only (#111866)

scripts/ci/check_os_marker_fakes.py flags test files that make the
interpreter believe it is on macOS (is_macos -> True, sys.platform ->
"darwin", platform.system -> "Darwin") while carrying no `macos_only`
marker: the macOS lane imports only marked files, so such a file is green
on Linux over a faked branch and never runs on the host it exists for.

A `# os-marker: ok — <why>` comment opts a host-independent line out.
_BASELINE holds the files that already faked macOS when the check landed;
a stale entry fails the check so the list can only burn down. Wired into
lint.yml next to the compat-pointer check; two invariant tests cover a
flagged fake vs marked/opted-out files and host-honest platform reads.
This commit is contained in:
teknium1
2026-09-15 20:04:56 -07:00
committed by Teknium
parent f0fd0650b5
commit bf1c28b480
+6
View File
@@ -185,6 +185,12 @@ jobs:
- name: Forbid in-tree use of plugin-compat pointers
run: python scripts/check_compat_pointers.py
# The OS lanes import only files carrying the matching marker, so a test that fakes
# macOS (is_macos -> True, sys.platform -> "darwin") without `macos_only` is green on
# Linux over a faked branch and never runs on macOS (#111866, AGENTS.md § Don't fake the host OS).
- name: Forbid unmarked macOS fakes in tests
run: python scripts/ci/check_os_marker_fakes.py
# Advisory: profile-scope hazard shapes on the lines this PR adds (child env from os.environ,
# raw os.getenv of a platform credential, HOME-only RPC binding, bare-PID liveness). One
# process serves many profiles; every pattern leaked the launch profile at least once. Printed